Accepted libvorbis 1.3.5-4+deb9u2 (source) into stable->embargoed, stable
Salvatore Bonaccorso
carnil at debian.org
Fri Mar 16 19:38:13 UTC 2018
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Fri, 16 Mar 2018 18:12:39 +0100
Source: libvorbis
Binary: libvorbis0a libvorbisenc2 libvorbisfile3 libvorbis-dev libvorbis-dbg
Architecture: source
Version: 1.3.5-4+deb9u2
Distribution: stretch-security
Urgency: high
Maintainer: Debian Xiph.org Maintainers <pkg-xiph-maint at lists.alioth.debian.org>
Changed-By: Salvatore Bonaccorso <carnil at debian.org>
Description:
libvorbis-dbg - debug files for Vorbis General Audio Compression Codec
libvorbis-dev - development files for Vorbis General Audio Compression Codec
libvorbis0a - decoder library for Vorbis General Audio Compression Codec
libvorbisenc2 - encoder library for Vorbis General Audio Compression Codec
libvorbisfile3 - high-level API for Vorbis General Audio Compression Codec
Changes:
libvorbis (1.3.5-4+deb9u2) stretch-security; urgency=high
.
* Non-maintainer upload by the Security Team.
* Prevent out-of-bounds write in codebook decoding (CVE-2018-5146)
Checksums-Sha1:
5c56cbc90b1be679fb013d0d9709f403a186c997 2566 libvorbis_1.3.5-4+deb9u2.dsc
e8ed3eab78daaa97b5c88b3c45fedb5b64c6928c 11532 libvorbis_1.3.5-4+deb9u2.debian.tar.xz
Checksums-Sha256:
b8480875bda11dd6e676329568b64ff81722426d9178ad28f4f1f267dbd59d96 2566 libvorbis_1.3.5-4+deb9u2.dsc
95cabe08962ce58df7e55766be4115802097689700dc8bacfb9f22d495df6955 11532 libvorbis_1.3.5-4+deb9u2.debian.tar.xz
Files:
996fbd9e9a684322cebcdd24e995a3ec 2566 libs optional libvorbis_1.3.5-4+deb9u2.dsc
6c739338d27b93a1117063250c62d692 11532 libs optional libvorbis_1.3.5-4+deb9u2.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAlqr+5lfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89El2AP/0fbOA+KDZ7nEbrHAqb7YRpmQGDurAob
Uel4MMizXHMN5dbZi8wWdDSKEPoKUPwRfbXyrXPPjZTwWQjEQd7Vq6XcxfaJmEY0
ORdhDTn1Em8SG/ZUHOYhc9A3n0xjvIGkm8W+CXfW+XG6JMb3t4frYR1MvizYInxn
TxjCUlCkyROk9t5lAqgR5H8dhoSSM5cPhl/eGYNjkUM1MSc1jZwhSw0GamybubcW
e5qbbp7VpFM47ko6Z3EGbZoHRsrI7LE88tpDh3Hr0CZap9cpDd3G3S19LeDTCmIE
7hj1rFN1VoZNIXgMl+buHwIjSe/KiaR0/+B9j6XE0VBaRbfvKHNuk2xQjSN3BDgZ
Gw0PXGjiC7Q2yvwxYrqSOFJgwVRfatsCCJcq2KkqVWKXzkZfyZhmp4aN0fEO99ir
opWph2WLjAJ3t6qvT5B1ntfJO8OO+/N1+UhuAk1JjPTZHtqIf74t6vcl+PKkmHEJ
sP8xUOFAoDIPWi5lvpsJfqgEt3IRY5YITjNwHEMpro+T+WshbIeykS0dnbIlFSHO
AdNQ33Fj4eFMkWA6/x6t8+dNVKT/xw9OHfux98wBbUn9V6LfYkRJQiUfWlFXoGJn
dcyMgKS7DfrGtFjI4zi4yuulpbcWr3mw6pQFp/f1AL9Qo6csdOoDagwChsDNFjGg
Aq5I/710onWB
=ylIK
-----END PGP SIGNATURE-----
More information about the pkg-xiph-maint
mailing list